2025 reflections and looking ahead to 2026 trends

With the festive season upon us, I may be posting a little less and instead singing Christmas songs with the family. So let’s look back at 2025 and anticipate 2026, based on interactions with my LinkedIn articles & posts: – Pseudonymisation & the concept of “personal data” were significant in 2025. 4 of my top […]

Read Analysis →

Legitimate interest and accountability in marketing

Appeal against Belgian DPA decision: important findings on legitimate interest, reasonable expectations and (non-)necessity of verifications of prior lawfulness. In a judgment of yesterday, the Market Court (Brussels Court of Appeal) lifted a reprimand for a company that had used personal data for marketing purposes. The legitimate interest considerations will be of great interest to […]

Read Analysis →

Podcast episode: Digital Omnibus and pseudonymisation

Podcast time again, with The Monopoly Report on the Digital Omnibus (focus on GDPR and ePrivacy changes). In this episode, Alan Chapell and I discuss the apparent intentions of the Commission, the link with case law of the EU Court of Justice, possible reactions from data protection regulators and more. Its publication this Wednesday ties […]

Read Analysis →

Pseudonymisation & “means reasonably likely to be used” for identification: when does data become personal?

As I was in a meeting when the European Data Protection Board opened registration for its pseudonymisation stakeholder event of 12 December 2025, I missed the short (approx. 1h) registration window and they placed me on a waiting list instead – a pity given my frequent interventions on the EU Court of Justice’s SRB judgment […]

Read Analysis →

What the EDPB AI opinion and Italian OpenAI fines mean for data models

Myth-busting time! This week, the EDPB published its Opinion on AI models & personal data, and then the Italian authority revealed it had fined OpenAI. But unlike what some are suggesting, the Italian decision *predates* the EDPB Opinion by a month. So let’s dispel a few myths surrounding that Opinion: – “Game changer”? The positions […]

Read Analysis →

My first thoughts on the EDPB opinion regarding AI models and personal data

Full analysis likely to come in the coming days, but some first thoughts on the EDPB’s “AI models & personal data” Opinion. In essence, the EDPB doesn’t exclude anything entirely but leaves it up to national supervisory authorities to make a call in cases they are handling – and while it doesn’t prohibit relying on […]

Read Analysis →

Personal data: relative concepts in the Digital Omnibus

Digital Omnibus & GDPR: I like some things & dislike others about the proposal, but want to push back against claims that the “personal data” definition change will weaken protection. Of course some data protection supervisory authorities will say this (non-personal data generally falls outside of their remit), but is there truly weakening of protection […]

Read Analysis →

Will jurisdictional conflicts separate NIS2 and GDPR fines in Belgium?

NIS2 vs GDPR: fines/injunctions in Belgium to be challenged before different courts? While the Belgian legislator has gradually been entrusting one single, specialised court with highly regulatory cases (essentially regarding telecom rules, financial services rules and data protection rules), it appears for now *not* to have chosen to entrust that same court, the Belgian Market […]

Read Analysis →

DMA-GDPR Guidelines: formal response to public consultation

When I pointed out issues with the DMA-GDPR Guidelines & resulting risks for *all* controllers (not just gatekeepers), the EDPB’s Gwendal Le Grand said something to the effect of “Don’t just post about it, submit a response”. So here we go, a copy of the response submitted yesterday to the public consultation by the Commission […]

Read Analysis →

Privacy-friendly analytics: dismissal of personal data complaint

Privacy-friendly analytics: dismissal of complaint for lack of evidence of processing of personal data. Reasoning of the Belgian DPA’s Inspection Service, quoting SRB and Breyer & confirming our arguments: 1. Insufficient evidence of a GDPR infringement The complainant did not provide concrete evidence demonstrating that his personal data had actually been processed by the provider (or […]

Read Analysis →